Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1620052 > unrolled thread

[PATCH 3.12 001/142] dm: flush queued bios when process blocks to avoid deadlock

Started byJiri Slaby <jslaby@suse.cz>
First post2017-04-10 17:40 +0200
Last post2017-04-10 18:20 +0200
Articles 20 on this page of 127 — 1 participant

Back to article view | Back to linux.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  [PATCH 3.12 001/142] dm: flush queued bios when process blocks to avoid deadlock Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 092/142] ext4: mark inode dirty after converting inline directory Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 134/142] ipv4: igmp: Allow removing groups from a removed interface Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 113/142] ALSA: seq: Fix race during FIFO resize Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 129/142] ACPI / PNP: Avoid conflicting resource reservations Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 123/142] padata: avoid race in reordering Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 135/142] HID: hid-lg: Fix immediate disconnection of Logitech Rumblepad 2 Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 142/142] tty/serial: atmel: fix race condition (TX+DMA) Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 131/142] ACPI / PNP: Reserve ACPI resources at the fs_initcall_sync stage Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 133/142] i2c: at91: manage unexpected RXRDY flag when starting a transfer Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 114/142] ACPI: Fix incompatibility with mcount-based function graph tracing Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 130/142] ACPI / resources: free memory on error in add_region_before() Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:40 +0200
    [PATCH 3.12 115/142] USB: fix linked-list corruption in rh_call_control() Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 093/142] mmc: sdhci: Do not disable interrupts while waiting for clock Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 105/142] sparc/ptrace: Preserve previous registers for short regset write Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 121/142] rtc: s35390a: improve irq handling Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 112/142] scsi: libsas: fix ata xfer length Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 109/142] sched/rt: Add a missing rescheduling point Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 111/142] scsi: mpt3sas: fix hang on ata passthrough commands Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 088/142] usb: hub: Fix crash after failure to read BOS descriptor Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 103/142] virtio_balloon: init 1st buffer in stats vq Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 100/142] crypto: algif_hash - avoid zero-sized array Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 122/142] KVM: kvm_io_bus_unregister_dev() should never fail Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 097/142] block: allow WRITE_SAME commands with the SG_IO ioctl Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 116/142] KVM: x86: clear bus pointer when destroyed Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 099/142] fbcon: Fix vc attr at deinit Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 089/142] uwb: i1480-dfu: fix NULL-deref at probe Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 081/142] USB: serial: option: add Quectel UC15, UC20, EC21, and EC25 modems Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 079/142] Input: kbtab - validate number of endpoints before using them Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 094/142] nl80211: fix dumpit error path RTNL deadlocks Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 118/142] rtc: s35390a: fix reading out alarm Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 101/142] xfrm_user: validate XFRM_MSG_NEWAE XFRMA_REPLAY_ESN_VAL replay_window Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 083/142] ACM gadget: fix endianness in notifications Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 102/142] xfrm_user: validate XFRM_MSG_NEWAE incoming ESN size harder Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 095/142] USB: usbtmc: add missing endpoint sanity check Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 120/142] rtc: s35390a: implement reset routine as suggested by the reference Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 096/142] xfs: clear _XBF_PAGES from buffers when readahead page Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 106/142] metag/ptrace: Preserve previous registers for short regset write Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 110/142] libceph: force GFP_NOIO for socket allocations Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 107/142] metag/ptrace: Provide default TXSTATUS for short NT_PRSTATUS Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 090/142] uwb: hwa-rc: fix NULL-deref at probe Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 108/142] metag/ptrace: Reject partial NT_METAG_RPIPE writes Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 098/142] uvcvideo: uvc_scan_fallback() for webcams with broken chain Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 104/142] c6x/ptrace: Remove useless PTRACE_SETREGSET implementation Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 091/142] mmc: ushc: fix NULL-deref at probe Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 117/142] mm, hugetlb: use pte_present() instead of pmd_present() in follow_huge_pmd() Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 126/142] Revert "cpufreq: fix garbage kobjects on errors during suspend/resume" Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 119/142] rtc: s35390a: make sure all members in the output are set Jiri Slaby <jslaby@suse.cz> - 2017-04-10 17:50 +0200
    [PATCH 3.12 080/142] ALSA: seq: Fix racy cell insertions during snd_seq_pool_done() Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 059/142] igb: add i211 to i210 PHY workaround Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 039/142] give up on gcc ilog2() constant optimizations Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 087/142] USB: wusbcore: fix NULL-deref at probe Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 069/142] USB: qcserial: add Sierra Wireless MC74xx/EM74xx Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 068/142] USB: qcserial: add HP lt4111 LTE/EV-DO/HSPA+ Gobi 4G Module Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 078/142] Input: cm109 - validate number of endpoints before using them Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 073/142] Input: i8042 - add noloop quirk for Dell Embedded Box PC 3000 Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 070/142] USB: qcserial: Add support for Quectel EC20 Mini PCIe module Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 067/142] USB: qcserial: Add support for Dell Wireless 5809e 4G Modem Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 046/142] ACPI / video: skip evaluating _DOD when it does not exist Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 086/142] USB: idmouse: fix NULL-deref at probe Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 052/142] perf/core: Fix event inheritance on fork() Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 074/142] Input: iforce - validate number of endpoints before using them Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 065/142] tcp: initialize icsk_ack.lrcvtime at session start time Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 064/142] ipv4: provide stronger user input validation in nl_fib_input() Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 060/142] net: properly release sk_frag.page Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 076/142] Input: hanwang - validate number of endpoints before using them Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 058/142] igb: Workaround for igb i210 firmware issue Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 066/142] libceph: don't set weight to IN when OSD is destroyed Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 082/142] USB: serial: qcserial: add Dell DW5811e Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 075/142] Input: ims-pcu - validate number of endpoints before using them Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 072/142] USB: qcserial: add Sierra Wireless EM74xx device ID Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 077/142] Input: yealink - validate number of endpoints before using them Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 071/142] USB: qcserial: add Dell Wireless 5809e Gobi 4G HSPA+ (rev3) Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 084/142] usb-core: Add LINEAR_FRAME_INTR_BINTERVAL USB quirk Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 085/142] USB: uss720: fix NULL-deref at probe Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 063/142] net/mlx5: Increase number of max QPs in default profile Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 049/142] KVM: PPC: Book3S PR: Fix illegal opcode emulation Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:00 +0200
    [PATCH 3.12 038/142] futex: Add missing error handling to FUTEX_REQUEUE_PI Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 034/142] dccp/tcp: fix routing redirect race Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 062/142] qmi_wwan: add Dell DW5811e Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 061/142] net: unix: properly re-increment inflight counter of GC discarded candidates Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 045/142] crypto: cryptd - Assign statesize properly Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 033/142] ipv6: avoid write to a possibly cloned skb Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 030/142] dccp: Unlock sock before calling sk_free() Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 048/142] Drivers: hv: avoid vfree() on crash Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 055/142] scsi: lpfc: Add shutdown method for kexec Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 043/142] netlink: remove mmapped netlink support Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 028/142] net: don't call strlen() on the user buffer in packet_bind_spkt() Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 032/142] uapi: fix linux/packet_diag.h userspace compilation error Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 053/142] cpufreq: Fix and clean up show_cpuinfo_cur_freq() Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 054/142] target/pscsi: Fix TYPE_TAPE + TYPE_MEDIMUM_CHANGER export Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 051/142] kernek/fork.c: allocate idle task for a CPU always on its local node Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 056/142] isdn/gigaset: fix NULL-deref at probe Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 026/142] ipv4: mask tos for input route Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 041/142] xfs: fix up xfs_swap_extent_forks inline extent handling Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 044/142] crypto: ghash-clmulni - Fix load failure Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 057/142] xen: do not re-use pirq number cached in pci device msi msg data Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 036/142] net sched actions: decrement module reference count after table flush. Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 047/142] Drivers: hv: balloon: don't crash when memory is added in non-sorted order Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 050/142] s390/pci: fix use after free in dma_init Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:10 +0200
    [PATCH 3.12 024/142] locking/static_keys: Add static_key_{en,dis}able() helpers Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 012/142] cpmac: remove hopeless #warning Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 035/142] dccp: fix memory leak during tear-down of unsuccessful connection request Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 017/142] USB: serial: safe_serial: fix information leak in completion handler Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 019/142] USB: iowarrior: fix NULL-deref at probe Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 015/142] usb: dwc3: gadget: make Set Endpoint Configuration macros safe Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 018/142] USB: serial: omninet: fix reference leaks at open Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 005/142] USB: serial: digi_acceleport: fix OOB data sanity check Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 029/142] net: net_enable_timestamp() can be called from irq contexts Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 004/142] xhci: fix 10 second timeout on removal of PCI hotpluggable xhci controllers Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 016/142] usb: host: xhci-plat: Fix timeout on removal of hot pluggable xhci controllers Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 007/142] crypto: improve gcc optimization flags for serpent and wp512 Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 013/142] MIPS: DEC: Avoid la pseudo-instruction in delay slots Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 025/142] vxlan: correctly validate VXLAN ID against VXLAN_N_VID Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 014/142] tracing: Add #undef to fix compile error Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 002/142] xfs: pass total block res. as total xfs_bmapi_write() parameter Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 009/142] MIPS: ip22: Fix ip28 build for modern gcc Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 011/142] MIPS: ralink: Cosmetic change to prom_init(). Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 010/142] mtd: pmcmsp: use kstrndup instead of kmalloc+strncpy Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 022/142] USB: serial: io_ti: fix information leak in completion handler Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 020/142] USB: iowarrior: fix NULL-deref in write Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 008/142] MIPS: ip27: Disable qlge driver in defconfig Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 021/142] USB: serial: io_ti: fix NULL-deref in interrupt callback Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 031/142] tcp: fix various issues for sockets morphing to listen state Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 006/142] USB: serial: digi_acceleport: fix OOB-event processing Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 027/142] l2tp: avoid use-after-free caused by l2tp_ip_backlog_recv Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200
    [PATCH 3.12 003/142] mm/huge_memory.c: respect FOLL_FORCE/FOLL_COW for thp Jiri Slaby <jslaby@suse.cz> - 2017-04-10 18:20 +0200

Page 4 of 7 — ← Prev page 1 2 3 [4] 5 6 7  Next page →


#1620124 — [PATCH 3.12 052/142] perf/core: Fix event inheritance on fork()

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:00 +0200
Subject[PATCH 3.12 052/142] perf/core: Fix event inheritance on fork()
Message-ID<tuJTt-2D4-45@gated-at.bofh.it>
In reply to#1620052
From: Peter Zijlstra <peterz@infradead.org>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit e7cc4865f0f31698ef2f7aac01a50e78968985b7 upstream.

While hunting for clues to a use-after-free, Oleg spotted that
perf_event_init_context() can loose an error value with the result
that fork() can succeed even though we did not fully inherit the perf
event context.

Spotted-by: Oleg Nesterov <oleg@redhat.com>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Cc: Alexander Shishkin <alexander.shishkin@linux.intel.com>
Cc: Arnaldo Carvalho de Melo <acme@kernel.org>
Cc: Arnaldo Carvalho de Melo <acme@redhat.com>
Cc: Dmitry Vyukov <dvyukov@google.com>
Cc: Frederic Weisbecker <fweisbec@gmail.com>
Cc: Jiri Olsa <jolsa@redhat.com>
Cc: Linus Torvalds <torvalds@linux-foundation.org>
Cc: Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Stephane Eranian <eranian@google.com>
Cc: Thomas Gleixner <tglx@linutronix.de>
Cc: Vince Weaver <vincent.weaver@maine.edu>
Cc: oleg@redhat.com
Fixes: 889ff0150661 ("perf/core: Split context's event group list into pinned and non-pinned lists")
Link: http://lkml.kernel.org/r/20170316125823.190342547@infradead.org
Signed-off-by: Ingo Molnar <mingo@kernel.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 kernel/events/core.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/kernel/events/core.c b/kernel/events/core.c
index a4a1516f3efc..0a360d3868c5 100644
--- a/kernel/events/core.c
+++ b/kernel/events/core.c
@@ -7754,7 +7754,7 @@ int perf_event_init_context(struct task_struct *child, int ctxn)
 		ret = inherit_task_group(event, parent, parent_ctx,
 					 child, ctxn, &inherited_all);
 		if (ret)
-			break;
+			goto out_unlock;
 	}
 
 	/*
@@ -7770,7 +7770,7 @@ int perf_event_init_context(struct task_struct *child, int ctxn)
 		ret = inherit_task_group(event, parent, parent_ctx,
 					 child, ctxn, &inherited_all);
 		if (ret)
-			break;
+			goto out_unlock;
 	}
 
 	raw_spin_lock_irqsave(&parent_ctx->lock, flags);
@@ -7798,6 +7798,7 @@ int perf_event_init_context(struct task_struct *child, int ctxn)
 	}
 
 	raw_spin_unlock_irqrestore(&parent_ctx->lock, flags);
+out_unlock:
 	mutex_unlock(&parent_ctx->mutex);
 
 	perf_unpin_context(parent_ctx);
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620125 — [PATCH 3.12 074/142] Input: iforce - validate number of endpoints before using them

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:00 +0200
Subject[PATCH 3.12 074/142] Input: iforce - validate number of endpoints before using them
Message-ID<tuJTt-2D4-41@gated-at.bofh.it>
In reply to#1620052
From: Johan Hovold <johan@kernel.org>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 59cf8bed44a79ec42303151dd014fdb6434254bb upstream.

Make sure to check the number of endpoints to avoid dereferencing a
NULL-pointer or accessing memory that lie beyond the end of the endpoint
array should a malicious device lack the expected endpoints.

Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/input/joystick/iforce/iforce-usb.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/input/joystick/iforce/iforce-usb.c b/drivers/input/joystick/iforce/iforce-usb.c
index d96aa27dfcdc..db64adfbe1af 100644
--- a/drivers/input/joystick/iforce/iforce-usb.c
+++ b/drivers/input/joystick/iforce/iforce-usb.c
@@ -141,6 +141,9 @@ static int iforce_usb_probe(struct usb_interface *intf,
 
 	interface = intf->cur_altsetting;
 
+	if (interface->desc.bNumEndpoints < 2)
+		return -ENODEV;
+
 	epirq = &interface->endpoint[0].desc;
 	epout = &interface->endpoint[1].desc;
 
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620126 — [PATCH 3.12 065/142] tcp: initialize icsk_ack.lrcvtime at session start time

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:00 +0200
Subject[PATCH 3.12 065/142] tcp: initialize icsk_ack.lrcvtime at session start time
Message-ID<tuJTu-2D4-57@gated-at.bofh.it>
In reply to#1620052
From: Eric Dumazet <edumazet@google.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit 15bb7745e94a665caf42bfaabf0ce062845b533b ]

icsk_ack.lrcvtime has a 0 value at socket creation time.

tcpi_last_data_recv can have bogus value if no payload is ever received.

This patch initializes icsk_ack.lrcvtime for active sessions
in tcp_finish_connect(), and for passive sessions in
tcp_create_openreq_child()

Signed-off-by: Eric Dumazet <edumazet@google.com>
Acked-by: Neal Cardwell <ncardwell@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
---
 net/ipv4/tcp_input.c     | 2 +-
 net/ipv4/tcp_minisocks.c | 1 +
 2 files changed, 2 insertions(+), 1 deletion(-)

diff --git a/net/ipv4/tcp_input.c b/net/ipv4/tcp_input.c
index 9eef76176704..7789595a1009 100644
--- a/net/ipv4/tcp_input.c
+++ b/net/ipv4/tcp_input.c
@@ -5292,6 +5292,7 @@ void tcp_finish_connect(struct sock *sk, struct sk_buff *skb)
 	struct inet_connection_sock *icsk = inet_csk(sk);
 
 	tcp_set_state(sk, TCP_ESTABLISHED);
+	icsk->icsk_ack.lrcvtime = tcp_time_stamp;
 
 	if (skb != NULL) {
 		icsk->icsk_af_ops->sk_rx_dst_set(sk, skb);
@@ -5492,7 +5493,6 @@ static int tcp_rcv_synsent_state_process(struct sock *sk, struct sk_buff *skb,
 			 * to stand against the temptation 8)     --ANK
 			 */
 			inet_csk_schedule_ack(sk);
-			icsk->icsk_ack.lrcvtime = tcp_time_stamp;
 			tcp_enter_quickack_mode(sk);
 			inet_csk_reset_xmit_timer(sk, ICSK_TIME_DACK,
 						  TCP_DELACK_MAX, TCP_RTO_MAX);
diff --git a/net/ipv4/tcp_minisocks.c b/net/ipv4/tcp_minisocks.c
index 58a3e69aef64..34fe583eeef3 100644
--- a/net/ipv4/tcp_minisocks.c
+++ b/net/ipv4/tcp_minisocks.c
@@ -403,6 +403,7 @@ struct sock *tcp_create_openreq_child(struct sock *sk, struct request_sock *req,
 		newtp->srtt = 0;
 		newtp->mdev = TCP_TIMEOUT_INIT;
 		newicsk->icsk_rto = TCP_TIMEOUT_INIT;
+		newicsk->icsk_ack.lrcvtime = tcp_time_stamp;
 
 		newtp->packets_out = 0;
 		newtp->retrans_out = 0;
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620127 — [PATCH 3.12 064/142] ipv4: provide stronger user input validation in nl_fib_input()

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:00 +0200
Subject[PATCH 3.12 064/142] ipv4: provide stronger user input validation in nl_fib_input()
Message-ID<tuJTt-2D4-47@gated-at.bofh.it>
In reply to#1620052
From: Eric Dumazet <edumazet@google.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit c64c0b3cac4c5b8cb093727d2c19743ea3965c0b ]

Alexander reported a KMSAN splat caused by reads of uninitialized
field (tb_id_in) from user provided struct fib_result_nl

It turns out nl_fib_input() sanity tests on user input is a bit
wrong :

User can pretend nlh->nlmsg_len is big enough, but provide
at sendmsg() time a too small buffer.

Reported-by: Alexander Potapenko <glider@google.com>
Signed-off-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
---
 net/ipv4/fib_frontend.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/net/ipv4/fib_frontend.c b/net/ipv4/fib_frontend.c
index 3d3966bf3df6..4a30de61bec1 100644
--- a/net/ipv4/fib_frontend.c
+++ b/net/ipv4/fib_frontend.c
@@ -965,7 +965,8 @@ static void nl_fib_input(struct sk_buff *skb)
 
 	net = sock_net(skb->sk);
 	nlh = nlmsg_hdr(skb);
-	if (skb->len < NLMSG_HDRLEN || skb->len < nlh->nlmsg_len ||
+	if (skb->len < nlmsg_total_size(sizeof(*frn)) ||
+	    skb->len < nlh->nlmsg_len ||
 	    nlmsg_len(nlh) < sizeof(*frn))
 		return;
 
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620129 — [PATCH 3.12 060/142] net: properly release sk_frag.page

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:00 +0200
Subject[PATCH 3.12 060/142] net: properly release sk_frag.page
Message-ID<tuJTu-2D4-63@gated-at.bofh.it>
In reply to#1620052
From: Eric Dumazet <edumazet@google.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit 22a0e18eac7a9e986fec76c60fa4a2926d1291e2 ]

I mistakenly added the code to release sk->sk_frag in
sk_common_release() instead of sk_destruct()

TCP sockets using sk->sk_allocation == GFP_ATOMIC do no call
sk_common_release() at close time, thus leaking one (order-3) page.

iSCSI is using such sockets.

Fixes: 5640f7685831 ("net: use a per task frag allocator")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
---
 net/core/sock.c | 10 +++++-----
 1 file changed, 5 insertions(+), 5 deletions(-)

diff --git a/net/core/sock.c b/net/core/sock.c
index d765d6411a5b..046a72affe69 100644
--- a/net/core/sock.c
+++ b/net/core/sock.c
@@ -1425,6 +1425,11 @@ static void __sk_free(struct sock *sk)
 		pr_debug("%s: optmem leakage (%d bytes) detected\n",
 			 __func__, atomic_read(&sk->sk_omem_alloc));
 
+	if (sk->sk_frag.page) {
+		put_page(sk->sk_frag.page);
+		sk->sk_frag.page = NULL;
+	}
+
 	if (sk->sk_peer_cred)
 		put_cred(sk->sk_peer_cred);
 	put_pid(sk->sk_peer_pid);
@@ -2660,11 +2665,6 @@ void sk_common_release(struct sock *sk)
 
 	sk_refcnt_debug_release(sk);
 
-	if (sk->sk_frag.page) {
-		put_page(sk->sk_frag.page);
-		sk->sk_frag.page = NULL;
-	}
-
 	sock_put(sk);
 }
 EXPORT_SYMBOL(sk_common_release);
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620130 — [PATCH 3.12 076/142] Input: hanwang - validate number of endpoints before using them

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:00 +0200
Subject[PATCH 3.12 076/142] Input: hanwang - validate number of endpoints before using them
Message-ID<tuJTu-2D4-55@gated-at.bofh.it>
In reply to#1620052
From: Johan Hovold <johan@kernel.org>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit ba340d7b83703768ce566f53f857543359aa1b98 upstream.

Make sure to check the number of endpoints to avoid dereferencing a
NULL-pointer should a malicious device lack endpoints.

Fixes: bba5394ad3bd ("Input: add support for Hanwang tablets")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/input/tablet/hanwang.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/input/tablet/hanwang.c b/drivers/input/tablet/hanwang.c
index 5cc04124995c..263c85e72e14 100644
--- a/drivers/input/tablet/hanwang.c
+++ b/drivers/input/tablet/hanwang.c
@@ -341,6 +341,9 @@ static int hanwang_probe(struct usb_interface *intf, const struct usb_device_id
 	int error;
 	int i;
 
+	if (intf->cur_altsetting->desc.bNumEndpoints < 1)
+		return -ENODEV;
+
 	hanwang = kzalloc(sizeof(struct hanwang), GFP_KERNEL);
 	input_dev = input_allocate_device();
 	if (!hanwang || !input_dev) {
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620133 — [PATCH 3.12 058/142] igb: Workaround for igb i210 firmware issue

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:00 +0200
Subject[PATCH 3.12 058/142] igb: Workaround for igb i210 firmware issue
Message-ID<tuJTu-2D4-61@gated-at.bofh.it>
In reply to#1620052
From: Chris J Arges <christopherarges@gmail.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit 4e684f59d760a2c7c716bb60190783546e2d08a1 ]

Sometimes firmware may not properly initialize I347AT4_PAGE_SELECT causing
the probe of an igb i210 NIC to fail. This patch adds an addition zeroing
of this register during igb_get_phy_id to workaround this issue.

Thanks for Jochen Henneberg for the idea and original patch.

Signed-off-by: Chris J Arges <christopherarges@gmail.com>
Tested-by: Aaron Brown <aaron.f.brown@intel.com>
Signed-off-by: Jeff Kirsher <jeffrey.t.kirsher@intel.com>
Signed-off-by: Sasha Levin <alexander.levin@verizon.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/net/ethernet/intel/igb/e1000_phy.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/net/ethernet/intel/igb/e1000_phy.c b/drivers/net/ethernet/intel/igb/e1000_phy.c
index ad2b74d95138..bd91752760d0 100644
--- a/drivers/net/ethernet/intel/igb/e1000_phy.c
+++ b/drivers/net/ethernet/intel/igb/e1000_phy.c
@@ -87,6 +87,10 @@ s32 igb_get_phy_id(struct e1000_hw *hw)
 	s32 ret_val = 0;
 	u16 phy_id;
 
+	/* ensure PHY page selection to fix misconfigured i210 */
+	if (hw->mac.type == e1000_i210)
+		phy->ops.write_reg(hw, I347AT4_PAGE_SELECT, 0);
+
 	ret_val = phy->ops.read_reg(hw, PHY_ID1, &phy_id);
 	if (ret_val)
 		goto out;
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620135 — [PATCH 3.12 066/142] libceph: don't set weight to IN when OSD is destroyed

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:00 +0200
Subject[PATCH 3.12 066/142] libceph: don't set weight to IN when OSD is destroyed
Message-ID<tuJTu-2D4-71@gated-at.bofh.it>
In reply to#1620052
From: Ilya Dryomov <idryomov@gmail.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit b581a5854eee4b7851dedb0f8c2ceb54fb902c06 upstream.

Since ceph.git commit 4e28f9e63644 ("osd/OSDMap: clear osd_info,
osd_xinfo on osd deletion"), weight is set to IN when OSD is deleted.
This changes the result of applying an incremental for clients, not
just OSDs.  Because CRUSH computations are obviously affected,
pre-4e28f9e63644 servers disagree with post-4e28f9e63644 clients on
object placement, resulting in misdirected requests.

Mirrors ceph.git commit a6009d1039a55e2c77f431662b3d6cc5a8e8e63f.

Fixes: 930c53286977 ("libceph: apply new_state before new_up_client on incrementals")
Link: http://tracker.ceph.com/issues/19122
Signed-off-by: Ilya Dryomov <idryomov@gmail.com>
Reviewed-by: Sage Weil <sage@redhat.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 net/ceph/osdmap.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/net/ceph/osdmap.c b/net/ceph/osdmap.c
index c1de8d404c47..26e2235356c5 100644
--- a/net/ceph/osdmap.c
+++ b/net/ceph/osdmap.c
@@ -870,7 +870,6 @@ static int decode_new_up_state_weight(void **p, void *end,
 		if ((map->osd_state[osd] & CEPH_OSD_EXISTS) &&
 		    (xorstate & CEPH_OSD_EXISTS)) {
 			pr_info("osd%d does not exist\n", osd);
-			map->osd_weight[osd] = CEPH_OSD_IN;
 			memset(map->osd_addr + osd, 0, sizeof(*map->osd_addr));
 			map->osd_state[osd] = 0;
 		} else {
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620137 — [PATCH 3.12 082/142] USB: serial: qcserial: add Dell DW5811e

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:00 +0200
Subject[PATCH 3.12 082/142] USB: serial: qcserial: add Dell DW5811e
Message-ID<tuJTu-2D4-77@gated-at.bofh.it>
In reply to#1620052
From: Bjørn Mork <bjorn@mork.no>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 436ecf5519d892397af133a79ccd38a17c25fa51 upstream.

This is a Dell branded Sierra Wireless EM7455.

Signed-off-by: Bjørn Mork <bjorn@mork.no>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/usb/serial/qcserial.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/usb/serial/qcserial.c b/drivers/usb/serial/qcserial.c
index 25f97da78989..c811c2dc1ae3 100644
--- a/drivers/usb/serial/qcserial.c
+++ b/drivers/usb/serial/qcserial.c
@@ -166,6 +166,8 @@ static const struct usb_device_id id_table[] = {
 	{DEVICE_SWI(0x413c, 0x81a9)},	/* Dell Wireless 5808e Gobi(TM) 4G LTE Mobile Broadband Card */
 	{DEVICE_SWI(0x413c, 0x81b1)},	/* Dell Wireless 5809e Gobi(TM) 4G LTE Mobile Broadband Card */
 	{DEVICE_SWI(0x413c, 0x81b3)},	/* Dell Wireless 5809e Gobi(TM) 4G LTE Mobile Broadband Card (rev3) */
+	{DEVICE_SWI(0x413c, 0x81b5)},	/* Dell Wireless 5811e QDL */
+	{DEVICE_SWI(0x413c, 0x81b6)},	/* Dell Wireless 5811e QDL */
 
 	{ }				/* Terminating entry */
 };
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620138 — [PATCH 3.12 075/142] Input: ims-pcu - validate number of endpoints before using them

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:00 +0200
Subject[PATCH 3.12 075/142] Input: ims-pcu - validate number of endpoints before using them
Message-ID<tuJTv-2D4-85@gated-at.bofh.it>
In reply to#1620052
From: Johan Hovold <johan@kernel.org>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 1916d319271664241b7aa0cd2b05e32bdb310ce9 upstream.

Make sure to check the number of endpoints to avoid dereferencing a
NULL-pointer should a malicious device lack control-interface endpoints.

Fixes: 628329d52474 ("Input: add IMS Passenger Control Unit driver")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/input/misc/ims-pcu.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/input/misc/ims-pcu.c b/drivers/input/misc/ims-pcu.c
index 77164dc1bedd..8fb814ccfd7a 100644
--- a/drivers/input/misc/ims-pcu.c
+++ b/drivers/input/misc/ims-pcu.c
@@ -1437,6 +1437,10 @@ static int ims_pcu_parse_cdc_data(struct usb_interface *intf, struct ims_pcu *pc
 		return -EINVAL;
 
 	alt = pcu->ctrl_intf->cur_altsetting;
+
+	if (alt->desc.bNumEndpoints < 1)
+		return -ENODEV;
+
 	pcu->ep_ctrl = &alt->endpoint[0].desc;
 	pcu->max_ctrl_size = usb_endpoint_maxp(pcu->ep_ctrl);
 
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620139 — [PATCH 3.12 072/142] USB: qcserial: add Sierra Wireless EM74xx device ID

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:00 +0200
Subject[PATCH 3.12 072/142] USB: qcserial: add Sierra Wireless EM74xx device ID
Message-ID<tuJTv-2D4-79@gated-at.bofh.it>
In reply to#1620052
From: Bjørn Mork <bjorn@mork.no>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 04fdbc825ffc02fb098964b92de802fff44e73fd upstream.

The MC74xx and EM74xx modules use different IDs by default, according
to the Lenovo EM7455 driver for Windows.

Signed-off-by: Bjørn Mork <bjorn@mork.no>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/usb/serial/qcserial.c | 6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/drivers/usb/serial/qcserial.c b/drivers/usb/serial/qcserial.c
index 68ec0b1bdc18..25f97da78989 100644
--- a/drivers/usb/serial/qcserial.c
+++ b/drivers/usb/serial/qcserial.c
@@ -155,8 +155,10 @@ static const struct usb_device_id id_table[] = {
 	{DEVICE_SWI(0x1199, 0x9056)},	/* Sierra Wireless Modem */
 	{DEVICE_SWI(0x1199, 0x9060)},	/* Sierra Wireless Modem */
 	{DEVICE_SWI(0x1199, 0x9061)},	/* Sierra Wireless Modem */
-	{DEVICE_SWI(0x1199, 0x9070)},	/* Sierra Wireless MC74xx/EM74xx */
-	{DEVICE_SWI(0x1199, 0x9071)},	/* Sierra Wireless MC74xx/EM74xx */
+	{DEVICE_SWI(0x1199, 0x9070)},	/* Sierra Wireless MC74xx */
+	{DEVICE_SWI(0x1199, 0x9071)},	/* Sierra Wireless MC74xx */
+	{DEVICE_SWI(0x1199, 0x9078)},	/* Sierra Wireless EM74xx */
+	{DEVICE_SWI(0x1199, 0x9079)},	/* Sierra Wireless EM74xx */
 	{DEVICE_SWI(0x413c, 0x81a2)},	/* Dell Wireless 5806 Gobi(TM) 4G LTE Mobile Broadband Card */
 	{DEVICE_SWI(0x413c, 0x81a3)},	/* Dell Wireless 5570 HSPA+ (42Mbps) Mobile Broadband Card */
 	{DEVICE_SWI(0x413c, 0x81a4)},	/* Dell Wireless 5570e HSPA+ (42Mbps) Mobile Broadband Card */
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620140 — [PATCH 3.12 077/142] Input: yealink - validate number of endpoints before using them

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:00 +0200
Subject[PATCH 3.12 077/142] Input: yealink - validate number of endpoints before using them
Message-ID<tuJTv-2D4-95@gated-at.bofh.it>
In reply to#1620052
From: Johan Hovold <johan@kernel.org>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 5cc4a1a9f5c179795c8a1f2b0f4361829d6a070e upstream.

Make sure to check the number of endpoints to avoid dereferencing a
NULL-pointer should a malicious device lack endpoints.

Fixes: aca951a22a1d ("[PATCH] input-driver-yealink-P1K-usb-phone")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Dmitry Torokhov <dmitry.torokhov@gmail.com>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/input/misc/yealink.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/input/misc/yealink.c b/drivers/input/misc/yealink.c
index 285a5bd6cbc9..3b6fdb389a2d 100644
--- a/drivers/input/misc/yealink.c
+++ b/drivers/input/misc/yealink.c
@@ -876,6 +876,10 @@ static int usb_probe(struct usb_interface *intf, const struct usb_device_id *id)
 	int ret, pipe, i;
 
 	interface = intf->cur_altsetting;
+
+	if (interface->desc.bNumEndpoints < 1)
+		return -ENODEV;
+
 	endpoint = &interface->endpoint[0].desc;
 	if (!usb_endpoint_is_int_in(endpoint))
 		return -ENODEV;
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620141 — [PATCH 3.12 071/142] USB: qcserial: add Dell Wireless 5809e Gobi 4G HSPA+ (rev3)

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:00 +0200
Subject[PATCH 3.12 071/142] USB: qcserial: add Dell Wireless 5809e Gobi 4G HSPA+ (rev3)
Message-ID<tuJTv-2D4-99@gated-at.bofh.it>
In reply to#1620052
From: Patrik Halfar <patrik_halfar@halfarit.cz>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 013dd239d6220a4e0dfdf0d45a82c34f1fd73deb upstream.

New revision of Dell Wireless 5809e Gobi 4G HSPA+ Mobile Broadband Card
has new idProduct.

Bus 002 Device 006: ID 413c:81b3 Dell Computer Corp.
Device Descriptor:
  bLength                18
  bDescriptorType         1
  bcdUSB               2.00
  bDeviceClass            0
  bDeviceSubClass         0
  bDeviceProtocol         0
  bMaxPacketSize0        64
  idVendor           0x413c Dell Computer Corp.
  idProduct          0x81b3
  bcdDevice            0.06
  iManufacturer           1 Sierra Wireless, Incorporated
  iProduct                2 Dell Wireless 5809e Gobi™ 4G HSPA+ Mobile Broadband Card
  iSerial                 3
  bNumConfigurations      2

Signed-off-by: Patrik Halfar <patrik_halfar@halfarit.cz>
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/usb/serial/qcserial.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/usb/serial/qcserial.c b/drivers/usb/serial/qcserial.c
index 2c9a44523991..68ec0b1bdc18 100644
--- a/drivers/usb/serial/qcserial.c
+++ b/drivers/usb/serial/qcserial.c
@@ -163,6 +163,7 @@ static const struct usb_device_id id_table[] = {
 	{DEVICE_SWI(0x413c, 0x81a8)},	/* Dell Wireless 5808 Gobi(TM) 4G LTE Mobile Broadband Card */
 	{DEVICE_SWI(0x413c, 0x81a9)},	/* Dell Wireless 5808e Gobi(TM) 4G LTE Mobile Broadband Card */
 	{DEVICE_SWI(0x413c, 0x81b1)},	/* Dell Wireless 5809e Gobi(TM) 4G LTE Mobile Broadband Card */
+	{DEVICE_SWI(0x413c, 0x81b3)},	/* Dell Wireless 5809e Gobi(TM) 4G LTE Mobile Broadband Card (rev3) */
 
 	{ }				/* Terminating entry */
 };
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620144 — [PATCH 3.12 084/142] usb-core: Add LINEAR_FRAME_INTR_BINTERVAL USB quirk

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:00 +0200
Subject[PATCH 3.12 084/142] usb-core: Add LINEAR_FRAME_INTR_BINTERVAL USB quirk
Message-ID<tuJTv-2D4-93@gated-at.bofh.it>
In reply to#1620052
From: Samuel Thibault <samuel.thibault@ens-lyon.org>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 3243367b209faed5c320a4e5f9a565ee2a2ba958 upstream.

Some USB 2.0 devices erroneously report millisecond values in
bInterval. The generic config code manages to catch most of them,
but in some cases it's not completely enough.

The case at stake here is a USB 2.0 braille device, which wants to
announce 10ms and thus sets bInterval to 10, but with the USB 2.0
computation that yields to 64ms.  It happens that one can type fast
enough to reach this interval and get the device buffers overflown,
leading to problematic latencies.  The generic config code does not
catch this case because the 64ms is considered a sane enough value.

This change thus adds a USB_QUIRK_LINEAR_FRAME_INTR_BINTERVAL quirk
to mark devices which actually report milliseconds in bInterval,
and marks Vario Ultra devices as needing it.

Signed-off-by: Samuel Thibault <samuel.thibault@ens-lyon.org>
Acked-by: Alan Stern <stern@rowland.harvard.edu>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/usb/core/config.c  | 10 ++++++++++
 drivers/usb/core/quirks.c  |  8 ++++++++
 include/linux/usb/quirks.h |  6 ++++++
 3 files changed, 24 insertions(+)

diff --git a/drivers/usb/core/config.c b/drivers/usb/core/config.c
index 15b39065f1dc..ee8e42064d25 100644
--- a/drivers/usb/core/config.c
+++ b/drivers/usb/core/config.c
@@ -248,6 +248,16 @@ static int usb_parse_endpoint(struct device *ddev, int cfgno, int inum,
 
 			/*
 			 * Adjust bInterval for quirked devices.
+			 */
+			/*
+			 * This quirk fixes bIntervals reported in ms.
+			 */
+			if (to_usb_device(ddev)->quirks &
+				USB_QUIRK_LINEAR_FRAME_INTR_BINTERVAL) {
+				n = clamp(fls(d->bInterval) + 3, i, j);
+				i = j = n;
+			}
+			/*
 			 * This quirk fixes bIntervals reported in
 			 * linear microframes.
 			 */
diff --git a/drivers/usb/core/quirks.c b/drivers/usb/core/quirks.c
index 094fe92ac21f..f792e6bea6b4 100644
--- a/drivers/usb/core/quirks.c
+++ b/drivers/usb/core/quirks.c
@@ -164,6 +164,14 @@ static const struct usb_device_id usb_quirk_list[] = {
 	/* M-Systems Flash Disk Pioneers */
 	{ USB_DEVICE(0x08ec, 0x1000), .driver_info = USB_QUIRK_RESET_RESUME },
 
+	/* Baum Vario Ultra */
+	{ USB_DEVICE(0x0904, 0x6101), .driver_info =
+			USB_QUIRK_LINEAR_FRAME_INTR_BINTERVAL },
+	{ USB_DEVICE(0x0904, 0x6102), .driver_info =
+			USB_QUIRK_LINEAR_FRAME_INTR_BINTERVAL },
+	{ USB_DEVICE(0x0904, 0x6103), .driver_info =
+			USB_QUIRK_LINEAR_FRAME_INTR_BINTERVAL },
+
 	/* Keytouch QWERTY Panel keyboard */
 	{ USB_DEVICE(0x0926, 0x3333), .driver_info =
 			USB_QUIRK_CONFIG_INTF_STRINGS },
diff --git a/include/linux/usb/quirks.h b/include/linux/usb/quirks.h
index 7eb814c60b5d..24872fc86962 100644
--- a/include/linux/usb/quirks.h
+++ b/include/linux/usb/quirks.h
@@ -50,4 +50,10 @@
 /* device can't handle Link Power Management */
 #define USB_QUIRK_NO_LPM			BIT(10)
 
+/*
+ * Device reports its bInterval as linear frames instead of the
+ * USB 2.0 calculation.
+ */
+#define USB_QUIRK_LINEAR_FRAME_INTR_BINTERVAL	BIT(11)
+
 #endif /* __LINUX_USB_QUIRKS_H */
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620146 — [PATCH 3.12 085/142] USB: uss720: fix NULL-deref at probe

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:00 +0200
Subject[PATCH 3.12 085/142] USB: uss720: fix NULL-deref at probe
Message-ID<tuJTv-2D4-97@gated-at.bofh.it>
In reply to#1620052
From: Johan Hovold <johan@kernel.org>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit f259ca3eed6e4b79ac3d5c5c9fb259fb46e86217 upstream.

Make sure to check the number of endpoints to avoid dereferencing a
NULL-pointer or accessing memory beyond the endpoint array should a
malicious device lack the expected endpoints.

Note that the endpoint access that causes the NULL-deref is currently
only used for debugging purposes during probe so the oops only happens
when dynamic debugging is enabled. This means the driver could be
rewritten to continue to accept device with only two endpoints, should
such devices exist.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Johan Hovold <johan@kernel.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 drivers/usb/misc/uss720.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/drivers/usb/misc/uss720.c b/drivers/usb/misc/uss720.c
index 40ef40affe83..3cb05eb5f1df 100644
--- a/drivers/usb/misc/uss720.c
+++ b/drivers/usb/misc/uss720.c
@@ -715,6 +715,11 @@ static int uss720_probe(struct usb_interface *intf,
 
 	interface = intf->cur_altsetting;
 
+	if (interface->desc.bNumEndpoints < 3) {
+		usb_put_dev(usbdev);
+		return -ENODEV;
+	}
+
 	/*
 	 * Allocate parport interface 
 	 */
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620148 — [PATCH 3.12 063/142] net/mlx5: Increase number of max QPs in default profile

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:00 +0200
Subject[PATCH 3.12 063/142] net/mlx5: Increase number of max QPs in default profile
Message-ID<tuJTw-2D4-101@gated-at.bofh.it>
In reply to#1620052
From: Maor Gottlieb <maorg@mellanox.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit 5f40b4ed975c26016cf41953b7510fe90718e21c ]

With ConnectX-4 sharing SRQs from the same space as QPs, we hit a
limit preventing some applications to allocate needed QPs amount.
Double the size to 256K.

[js] this is in another file in 3.12

Fixes: e126ba97dba9e ('mlx5: Add driver for Mellanox Connect-IB adapters')
Signed-off-by: Maor Gottlieb <maorg@mellanox.com>
Signed-off-by: Saeed Mahameed <saeedm@mellanox.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
---
 drivers/infiniband/hw/mlx5/main.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/infiniband/hw/mlx5/main.c b/drivers/infiniband/hw/mlx5/main.c
index 1300a377aca8..94f1408b391c 100644
--- a/drivers/infiniband/hw/mlx5/main.c
+++ b/drivers/infiniband/hw/mlx5/main.c
@@ -73,7 +73,7 @@ static struct mlx5_profile profile[] = {
 	[2] = {
 		.mask		= MLX5_PROF_MASK_QP_SIZE |
 				  MLX5_PROF_MASK_MR_CACHE,
-		.log_max_qp	= 17,
+		.log_max_qp	= 18,
 		.mr_cache[0]	= {
 			.size	= 500,
 			.limit	= 250
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620149 — [PATCH 3.12 049/142] KVM: PPC: Book3S PR: Fix illegal opcode emulation

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:00 +0200
Subject[PATCH 3.12 049/142] KVM: PPC: Book3S PR: Fix illegal opcode emulation
Message-ID<tuJTw-2D4-105@gated-at.bofh.it>
In reply to#1620052
From: Thomas Huth <thuth@redhat.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 708e75a3ee750dce1072134e630d66c4e6eaf63c upstream.

If kvmppc_handle_exit_pr() calls kvmppc_emulate_instruction() to emulate
one instruction (in the BOOK3S_INTERRUPT_H_EMUL_ASSIST case), it calls
kvmppc_core_queue_program() afterwards if kvmppc_emulate_instruction()
returned EMULATE_FAIL, so the guest gets an program interrupt for the
illegal opcode.
However, the kvmppc_emulate_instruction() also tried to inject a
program exception for this already, so the program interrupt gets
injected twice and the return address in srr0 gets destroyed.
All other callers of kvmppc_emulate_instruction() are also injecting
a program interrupt, and since the callers have the right knowledge
about the srr1 flags that should be used, it is the function
kvmppc_emulate_instruction() that should _not_ inject program
interrupts, so remove the kvmppc_core_queue_program() here.

This fixes the issue discovered by Laurent Vivier with kvm-unit-tests
where the logs are filled with these messages when the test tries
to execute an illegal instruction:

     Couldn't emulate instruction 0x00000000 (op 0 xop 0)
     kvmppc_handle_exit_pr: emulation at 700 failed (00000000)

Signed-off-by: Thomas Huth <thuth@redhat.com>
Reviewed-by: Alexander Graf <agraf@suse.de>
Tested-by: Laurent Vivier <lvivier@redhat.com>
Signed-off-by: Paul Mackerras <paulus@ozlabs.org>
Cc: Sumit Semwal <sumit.semwal@linaro.org>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 arch/powerpc/kvm/emulate.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/arch/powerpc/kvm/emulate.c b/arch/powerpc/kvm/emulate.c
index 751cd45f65a0..128651aa8437 100644
--- a/arch/powerpc/kvm/emulate.c
+++ b/arch/powerpc/kvm/emulate.c
@@ -471,7 +471,6 @@ int kvmppc_emulate_instruction(struct kvm_run *run, struct kvm_vcpu *vcpu)
 			advance = 0;
 			printk(KERN_ERR "Couldn't emulate instruction 0x%08x "
 			       "(op %d xop %d)\n", inst, get_op(inst), get_xop(inst));
-			kvmppc_core_queue_program(vcpu, 0);
 		}
 	}
 
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620151 — [PATCH 3.12 038/142] futex: Add missing error handling to FUTEX_REQUEUE_PI

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:10 +0200
Subject[PATCH 3.12 038/142] futex: Add missing error handling to FUTEX_REQUEUE_PI
Message-ID<tuK37-2W1-3@gated-at.bofh.it>
In reply to#1620052
From: Peter Zijlstra <peterz@infradead.org>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

commit 9bbb25afeb182502ca4f2c4f3f88af0681b34cae upstream.

Thomas spotted that fixup_pi_state_owner() can return errors and we
fail to unlock the rt_mutex in that case.

Reported-by: Thomas Gleixner <tglx@linutronix.de>
Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org>
Reviewed-by: Darren Hart <dvhart@linux.intel.com>
Cc: juri.lelli@arm.com
Cc: bigeasy@linutronix.de
Cc: xlpang@redhat.com
Cc: rostedt@goodmis.org
Cc: mathieu.desnoyers@efficios.com
Cc: jdesfossez@efficios.com
Cc: dvhart@infradead.org
Cc: bristot@redhat.com
Link: http://lkml.kernel.org/r/20170304093558.867401760@infradead.org
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 kernel/futex.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/kernel/futex.c b/kernel/futex.c
index 9667d9233289..566e2e0e56cf 100644
--- a/kernel/futex.c
+++ b/kernel/futex.c
@@ -2496,6 +2496,8 @@ static int futex_wait_requeue_pi(u32 __user *uaddr, unsigned int flags,
 		if (q.pi_state && (q.pi_state->owner != current)) {
 			spin_lock(q.lock_ptr);
 			ret = fixup_pi_state_owner(uaddr2, &q, current);
+			if (ret && rt_mutex_owner(&q.pi_state->pi_mutex) == current)
+				rt_mutex_unlock(&q.pi_state->pi_mutex);
 			/*
 			 * Drop the reference to the pi state which
 			 * the requeue_pi() code acquired for us.
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620152 — [PATCH 3.12 034/142] dccp/tcp: fix routing redirect race

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:10 +0200
Subject[PATCH 3.12 034/142] dccp/tcp: fix routing redirect race
Message-ID<tuK37-2W1-5@gated-at.bofh.it>
In reply to#1620052
From: Jon Maxwell <jmaxwell37@gmail.com>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit 45caeaa5ac0b4b11784ac6f932c0ad4c6b67cda0 ]

As Eric Dumazet pointed out this also needs to be fixed in IPv6.
v2: Contains the IPv6 tcp/Ipv6 dccp patches as well.

We have seen a few incidents lately where a dst_enty has been freed
with a dangling TCP socket reference (sk->sk_dst_cache) pointing to that
dst_entry. If the conditions/timings are right a crash then ensues when the
freed dst_entry is referenced later on. A Common crashing back trace is:

 #8 [] page_fault at ffffffff8163e648
    [exception RIP: __tcp_ack_snd_check+74]
.
.
 #9 [] tcp_rcv_established at ffffffff81580b64
#10 [] tcp_v4_do_rcv at ffffffff8158b54a
#11 [] tcp_v4_rcv at ffffffff8158cd02
#12 [] ip_local_deliver_finish at ffffffff815668f4
#13 [] ip_local_deliver at ffffffff81566bd9
#14 [] ip_rcv_finish at ffffffff8156656d
#15 [] ip_rcv at ffffffff81566f06
#16 [] __netif_receive_skb_core at ffffffff8152b3a2
#17 [] __netif_receive_skb at ffffffff8152b608
#18 [] netif_receive_skb at ffffffff8152b690
#19 [] vmxnet3_rq_rx_complete at ffffffffa015eeaf [vmxnet3]
#20 [] vmxnet3_poll_rx_only at ffffffffa015f32a [vmxnet3]
#21 [] net_rx_action at ffffffff8152bac2
#22 [] __do_softirq at ffffffff81084b4f
#23 [] call_softirq at ffffffff8164845c
#24 [] do_softirq at ffffffff81016fc5
#25 [] irq_exit at ffffffff81084ee5
#26 [] do_IRQ at ffffffff81648ff8

Of course it may happen with other NIC drivers as well.

It's found the freed dst_entry here:

 224 static bool tcp_in_quickack_mode(struct sock *sk)↩
 225 {↩
 226 ▹       const struct inet_connection_sock *icsk = inet_csk(sk);↩
 227 ▹       const struct dst_entry *dst = __sk_dst_get(sk);↩
 228 ↩
 229 ▹       return (dst && dst_metric(dst, RTAX_QUICKACK)) ||↩
 230 ▹       ▹       (icsk->icsk_ack.quick && !icsk->icsk_ack.pingpong);↩
 231 }↩

But there are other backtraces attributed to the same freed dst_entry in
netfilter code as well.

All the vmcores showed 2 significant clues:

- Remote hosts behind the default gateway had always been redirected to a
different gateway. A rtable/dst_entry will be added for that host. Making
more dst_entrys with lower reference counts. Making this more probable.

- All vmcores showed a postitive LockDroppedIcmps value, e.g:

LockDroppedIcmps                  267

A closer look at the tcp_v4_err() handler revealed that do_redirect() will run
regardless of whether user space has the socket locked. This can result in a
race condition where the same dst_entry cached in sk->sk_dst_entry can be
decremented twice for the same socket via:

do_redirect()->__sk_dst_check()-> dst_release().

Which leads to the dst_entry being prematurely freed with another socket
pointing to it via sk->sk_dst_cache and a subsequent crash.

To fix this skip do_redirect() if usespace has the socket locked. Instead let
the redirect take place later when user space does not have the socket
locked.

The dccp/IPv6 code is very similar in this respect, so fixing it there too.

As Eric Garver pointed out the following commit now invalidates routes. Which
can set the dst->obsolete flag so that ipv4_dst_check() returns null and
triggers the dst_release().

Fixes: ceb3320610d6 ("ipv4: Kill routes during PMTU/redirect updates.")
Cc: Eric Garver <egarver@redhat.com>
Cc: Hannes Sowa <hsowa@redhat.com>
Signed-off-by: Jon Maxwell <jmaxwell37@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
---
 net/dccp/ipv4.c     | 3 ++-
 net/dccp/ipv6.c     | 8 +++++---
 net/ipv4/tcp_ipv4.c | 3 ++-
 net/ipv6/tcp_ipv6.c | 8 +++++---
 4 files changed, 14 insertions(+), 8 deletions(-)

diff --git a/net/dccp/ipv4.c b/net/dccp/ipv4.c
index 4332b7c25af0..67f0f0652641 100644
--- a/net/dccp/ipv4.c
+++ b/net/dccp/ipv4.c
@@ -263,7 +263,8 @@ static void dccp_v4_err(struct sk_buff *skb, u32 info)
 
 	switch (type) {
 	case ICMP_REDIRECT:
-		dccp_do_redirect(skb, sk);
+		if (!sock_owned_by_user(sk))
+			dccp_do_redirect(skb, sk);
 		goto out;
 	case ICMP_SOURCE_QUENCH:
 		/* Just silently ignore these. */
diff --git a/net/dccp/ipv6.c b/net/dccp/ipv6.c
index 736fdedf9c85..c3ae00de1740 100644
--- a/net/dccp/ipv6.c
+++ b/net/dccp/ipv6.c
@@ -132,10 +132,12 @@ static void dccp_v6_err(struct sk_buff *skb, struct inet6_skb_parm *opt,
 	np = inet6_sk(sk);
 
 	if (type == NDISC_REDIRECT) {
-		struct dst_entry *dst = __sk_dst_check(sk, np->dst_cookie);
+		if (!sock_owned_by_user(sk)) {
+			struct dst_entry *dst = __sk_dst_check(sk, np->dst_cookie);
 
-		if (dst)
-			dst->ops->redirect(dst, sk, skb);
+			if (dst)
+				dst->ops->redirect(dst, sk, skb);
+		}
 		goto out;
 	}
 
diff --git a/net/ipv4/tcp_ipv4.c b/net/ipv4/tcp_ipv4.c
index c67d89ccadf7..129af2aa04d9 100644
--- a/net/ipv4/tcp_ipv4.c
+++ b/net/ipv4/tcp_ipv4.c
@@ -393,7 +393,8 @@ void tcp_v4_err(struct sk_buff *icmp_skb, u32 info)
 
 	switch (type) {
 	case ICMP_REDIRECT:
-		do_redirect(icmp_skb, sk);
+		if (!sock_owned_by_user(sk))
+			do_redirect(icmp_skb, sk);
 		goto out;
 	case ICMP_SOURCE_QUENCH:
 		/* Just silently ignore these. */
diff --git a/net/ipv6/tcp_ipv6.c b/net/ipv6/tcp_ipv6.c
index e5bafd576a13..7bec37d485d4 100644
--- a/net/ipv6/tcp_ipv6.c
+++ b/net/ipv6/tcp_ipv6.c
@@ -386,10 +386,12 @@ static void tcp_v6_err(struct sk_buff *skb, struct inet6_skb_parm *opt,
 	np = inet6_sk(sk);
 
 	if (type == NDISC_REDIRECT) {
-		struct dst_entry *dst = __sk_dst_check(sk, np->dst_cookie);
+		if (!sock_owned_by_user(sk)) {
+			struct dst_entry *dst = __sk_dst_check(sk, np->dst_cookie);
 
-		if (dst)
-			dst->ops->redirect(dst, sk, skb);
+			if (dst)
+				dst->ops->redirect(dst, sk, skb);
+		}
 		goto out;
 	}
 
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


#1620153 — [PATCH 3.12 062/142] qmi_wwan: add Dell DW5811e

FromJiri Slaby <jslaby@suse.cz>
Date2017-04-10 18:10 +0200
Subject[PATCH 3.12 062/142] qmi_wwan: add Dell DW5811e
Message-ID<tuK37-2W1-11@gated-at.bofh.it>
In reply to#1620052
From: Bjørn Mork <bjorn@mork.no>

3.12-stable review patch.  If anyone has any objections, please let me know.

===============

[ Upstream commit 6bd845d1cf98b45c634baacb8381436dad3c2dd0 ]

This is a Dell branded Sierra Wireless EM7455. It is operating in
MBIM mode by default, but can be configured to provide two QMI/RMNET
functions.

Signed-off-by: Bjørn Mork <bjorn@mork.no>
Signed-off-by: David S. Miller <davem@davemloft.net>
---
 drivers/net/usb/qmi_wwan.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/net/usb/qmi_wwan.c b/drivers/net/usb/qmi_wwan.c
index 40eabbb4bcd7..811b9cdb1824 100644
--- a/drivers/net/usb/qmi_wwan.c
+++ b/drivers/net/usb/qmi_wwan.c
@@ -829,6 +829,8 @@ static const struct usb_device_id products[] = {
 	{QMI_FIXED_INTF(0x413c, 0x81a9, 8)},	/* Dell Wireless 5808e Gobi(TM) 4G LTE Mobile Broadband Card */
 	{QMI_FIXED_INTF(0x413c, 0x81b1, 8)},	/* Dell Wireless 5809e Gobi(TM) 4G LTE Mobile Broadband Card */
 	{QMI_FIXED_INTF(0x413c, 0x81b3, 8)},	/* Dell Wireless 5809e Gobi(TM) 4G LTE Mobile Broadband Card (rev3) */
+	{QMI_FIXED_INTF(0x413c, 0x81b6, 8)},	/* Dell Wireless 5811e */
+	{QMI_FIXED_INTF(0x413c, 0x81b6, 10)},	/* Dell Wireless 5811e */
 	{QMI_FIXED_INTF(0x03f0, 0x4e1d, 8)},	/* HP lt4111 LTE/EV-DO/HSPA+ Gobi 4G Module */
 	{QMI_FIXED_INTF(0x22de, 0x9061, 3)},	/* WeTelecom WPD-600N */
 	{QMI_FIXED_INTF(0x1e0e, 0x9001, 5)},	/* SIMCom 7230E */
-- 
2.12.2

[toc] | [prev] | [next] | [standalone]


Page 4 of 7 — ← Prev page 1 2 3 [4] 5 6 7  Next page →

Back to top | Article view | linux.kernel


csiph-web